The analysis draws on a 16 July Red Oak Insights webinar featuring Eversheds Sutherland partner and co-head of the Securities Enforcement Group Brian Rubin, Manulife Wealth & Asset Management head of global distribution compliance Derek Stern and MirrorWeb vp of product Jamie Hoyle. The discussion was moderated by Red Oak chief supervision evangelist James Cella.
Eversheds Sutherland partner Brian Rubin said, “There are no existing AI rules”.
However, he argued that regulators do not need to introduce AI-specific requirements before examining how financial firms are using the technology. Existing rules covering supervision, communications, recordkeeping, conflicts of interest, Reg BI and fiduciary duties already apply when AI is involved in a firm’s processes.
FINRA’s Regulatory Notice 24-09 provides a clear example. The notice states, “If a firm is using Gen AI tools as part of its supervisory system—for the review of electronic correspondence, for instance—its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model.”
The regulator’s 2026 Regulatory Oversight Report has also elevated generative AI to a standalone focus area, reinforcing the expectation that firms should already have controls around their use of the technology.
The regulatory risks are no longer theoretical. The SEC has brought cases involving firms’ claims about their AI capabilities, while FINRA has taken action over a flawed automated identity-verification process linked to anti-money laundering controls. Neither case depended on a new AI-specific rule. Instead, the existing regulatory framework was applied to the way firms used technology and the outcomes it produced.
Rubin described this as a “show your work” environment, with regulators increasingly interested in how firms actually deploy AI rather than simply what their written policies say. That means firms need to understand who approved an AI system, what data it uses, how its outputs are validated and where human accountability sits.
Rubin compared the situation with the evolution of electronic communications. Rules originally designed around paper records were later applied to email and subsequently to off-channel communications such as WhatsApp and personal devices. The underlying rules did not necessarily change. Regulators applied existing requirements to new ways of communicating.
AI could create a similar challenge. Employees using unapproved AI platforms for client-related work may generate records outside the firm’s control, creating another version of an issue financial firms have already faced with off-channel communications.
One of the biggest unresolved questions concerns what firms should retain when AI is involved in a decision. There are currently no AI-specific retention periods covering prompts, intermediate outputs, decision logs and other operational data.
Rubin argued that firms should first establish whether an AI-generated record needs to be retained at all, rather than assuming every output carries the same regulatory weight. The position becomes clearer when AI-generated material is used for an existing regulated purpose. If an output is sent to a client, incorporated into a recommendation or used in marketing, existing retention requirements apply regardless of whether the material was created by a person or a model.
The more difficult issue is explainability. Firms need to be able to reconstruct how a decision was reached, what role AI played and where human oversight was applied. That becomes more complicated when models are updated or retired between the original decision and a later regulatory examination.
Rubin’s advice is to test that process before an examiner does. Firms should take a decision made six or 12 months ago and attempt to reconstruct how it was reached. If the necessary information is no longer available, that exposes a control gap that could become a regulatory problem.
AI is also changing the role of compliance teams within financial firms. Derek Stern said AI adoption at Manulife Wealth & Asset Management is being driven from senior leadership, with compliance involved alongside technology, legal and marketing teams while systems are still being developed.
The shift means compliance is increasingly being brought into the process before an AI system goes live rather than being asked to assess it after implementation. Stern said compliance is no longer the “department of no” or “sales prevention”, but is increasingly being viewed as a partner in deploying new technology.
His approach to assessing AI systems focuses on several areas, including how data is handled, where it is stored, who can access it and whether the system’s conclusions can be explained. Vendor governance is another consideration, with firms needing visibility into how providers manage model updates, testing and change management.
Human review remains another important control. Firms cannot simply rely on vendor assurances that an AI system will perform as expected. The technology needs to be tested against the firm’s own risk scenarios before it becomes part of a regulated workflow.
MirrorWeb vp of product Jamie Hoyle warned against vendors promising fully automated compliance, saying, “you’ll hear [vendors] talk about putting compliance on autopilot and you should run for the hills.”
Instead, Hoyle pointed to the growing role of contextual systems that can assess communications against a firm’s own policies. For example, a system could identify that a dinner at a three-Michelin-star restaurant potentially breaches a firm’s $250 gift limit without requiring compliance teams to create a specific keyword for the restaurant.
The benefit is a move away from simply matching words towards understanding the circumstances surrounding a communication. But greater sophistication does not remove the need for oversight. Firms still need to be able to explain why a communication was flagged and demonstrate that the system is operating in line with their supervisory requirements.
The central message from the Red Oak Analysis is that financial firms cannot afford to wait for regulators to establish a dedicated AI framework before addressing governance. The technology may be new, but the underlying expectations are familiar. Documentation, explainability, recordkeeping, supervision and human accountability remain central to how financial firms manage regulatory risk.
Copyright © 2018 RegTech Analyst





